Health & Energy
Zuletzt aktualisiert am
For workloads run by or for healthcare providers, health and care insurers, and energy operators in Germany, and the teams building for them. The mountain is the same as for everyone; this page maps what this route demands of it, and adds nothing.
The regulatory map
Section titled “The regulatory map”What binds here, and what each regime asks of an architecture.
Cloud use in healthcare is statute. Section 393 SGB
V permits processing social and health data
in cloud services only within Germany, the EU or an equivalent state, and only by a provider with
a domestic establishment. It requires a current C5 attestation, Type 2 from July 2025, and, in
the same sentence, that the customer-side criteria from the attestation’s report are
implemented. The law itself splits the responsibility, which is SOV 8.3 with a statute behind
it; STACKIT’s side is the C5 Type
2 attestation.
Hospital and practice IT security. Section 393 grounds its measures in the neighbouring
provisions for hospitals and practices, section 391 among
them , and in the sector security standard
for insurers. The baseline is externally framed per actor class, which is SEC 1.1 with the
frame already chosen.
Energy runs critical infrastructure. Section 11 EnWG obliges network operators to protect the IT that a secure network operation depends on, with catalogues of security requirements issued by the regulator, and the KRITIS regime under the BSI act adds registration, incident reporting and audited technical measures for operators above threshold. Which duties bind is an operator-class question; that they centre on availability and incident reporting is not.
Health data is the strongest case of the tier criteria. Special categories of personal data under the GDPR’s article 9 are the textbook content of Tier 1, and health data is their textbook case. The residency and establishment requirements of section 393 turn what is elsewhere a preference into law.
The tier default
Section titled “The tier default”Tier 1, sovereignty-mandatory, for health data. Section 393 fixes where processing may happen and through whom, and health data meets the Tier 1 criteria on their own terms besides.
The energy side is decided per data set, SOV 1.3. Operational and market data commonly sit at
Tier 2 with the KRITIS duties running on availability rather than residency; control-adjacent
systems deserve the Tier 1 conversation. Either way the reasoning is recorded, SOV 1.2, and an
estate mixing both halves classifies per data set rather than per company.
The pillar weighting
Section titled “The pillar weighting”Four pillars shift; each shift traces to the map.
Sovereignty & Compliance leads. Placement and establishment are statutory (SOV 2),
telemetry and backups inherit the boundary (SOV 3), and the C5 customer-side criteria make the
responsibility split (SOV 8.3) the sentence an auditor starts from.
Security is elevated and classification-first. Health data makes SEC 3 the entry point:
classification, the copies, and encryption with a deliberate answer to who can decrypt
(SEC 7.3), which for health data is also SOV 4’s question.
Reliability is elevated, on the recovery half. Care does not pause for an outage and a
network does not wait for a restore. Backup and rehearsed restore (REL 8), and recovery
rehearsed against a stated time (REL 9.3), are the questions this sector’s incident history
asks; the KRITIS duties add reporting on top.
Operational Excellence is elevated as the evidence machine. OPS 3’s reviewed, versioned
changes are the record the attestation and the audits consume.
Performance Efficiency, Cost Optimization and Sustainability do not shift.
The statement core
Section titled “The statement core”What an assessment of a health or energy workload accounts for regardless of where the conversation went: each of these ends evidenced or in the risk register.
Sovereignty & Compliance
Section titled “Sovereignty & Compliance”| Statement | What makes it mandatory here |
|---|---|
SOV 1.1 | The tier decision per data set is where health and energy halves part ways |
SOV 1.3 | One estate, two regimes: classification is per data set or it is wrong |
SOV 2.1 | Placement is statutory for health data, not preferential |
SOV 2.2 | The untraced dependency is where a statutory boundary quietly breaks |
SOV 3.1 | Telemetry carries patient data the moment a log does |
SOV 3.3 | Backups and exports must hold the same boundary the statute draws |
SOV 6.2 | Jurisdiction of every processor is what the establishment requirement is about |
SOV 7.3 | Retention follows the obligation, and health obligations run long |
SOV 8.1 | Actor class decides which frame binds: practice, hospital, insurer, operator |
SOV 8.3 | The C5 customer-side criteria are law here, and unowned controls fail them |
Security
Section titled “Security”| Statement | What makes it mandatory here |
|---|---|
SEC 2.1 | Isolation strength for patient data is chosen from protection need, never default |
SEC 3.1 | Classification before placement is the order the statute assumes |
SEC 3.3 | Copies of health data inherit every obligation of the original |
SEC 7.2 | Encryption at rest including every copy is the floor for article 9 data |
SEC 7.3 | Who can technically decrypt health data must be a deliberate, recorded answer |
SEC 11.3 | Incidents here carry reporting duties; the response cannot be improvised |
Reliability and operations
Section titled “Reliability and operations”| Statement | What makes it mandatory here |
|---|---|
REL 1.2 | Availability targets follow care processes and network operation, per flow |
REL 1.4 | A statutory availability duty needs an accountable owner for its target |
REL 8.1 | The backup schedule is derived, because data loss here is not an inconvenience |
REL 8.2 | Copies out of a single failure’s reach, including the attacker’s, is the ransomware lesson |
REL 8.3 | A restore rehearsed into a clean environment is the only proof that counts |
REL 9.3 | Recovery rehearsed against the stated time, because the duty is continuity |
OPS 3.1 | The change record audits consume exists only as versioned definitions |
OPS 3.2 | An unreviewed change is a change without evidence |
Outside this page
Section titled “Outside this page”Medical devices and control systems. Software as a medical device and OT control systems carry their own regimes and safety cases. This page maps the cloud workload beside them, not the device or the plant.
The thresholds. Whether a specific operator is above a KRITIS threshold, and which sector standard applies in which version, are determinations for the operator’s compliance function. The page maps what the architecture must evidence once they bind.
Related
Section titled “Related”- Sovereignty & Compliance: the statutory half
- Reliability: the continuity half